CVE-2026-106577: ImageMagick: Code Injection in the postscript coders
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-31 and 6.9.13-56, unescaped or untrimmed values can inject code into output generated by PostScript coders. This issue is fixed in versions 7.1.2-31 and 6.9.13-56.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 7.1.2-31 - Upgrade
Upgrade
ImageMagickto a version that resolves this vulnerability.Fixed in 6.9.13-56
Event History
Frequently Asked Questions
Which deployments are affected?
ImageMagick versions earlier than 7.1.2-31 and 6.9.13-56 are affected when they generate output through PostScript coders. The provided data does not identify any additional platform-specific conditions.
What must an attacker be able to do to exploit this?
Exploitation requires network reachability, user interaction, and high attack complexity according to the supplied CVSS vector. The issue involves unescaped or untrimmed values being incorporated into output generated by PostScript coders, enabling code injection.
What is the impact if exploitation succeeds?
The supplied CVSS vector indicates high confidentiality impact, with no integrity or availability impact. Scope is unchanged.
How can the issue be remediated?
Upgrade ImageMagick to version 7.1.2-31 or later on the 7.x line, or 6.9.13-56 or later on the 6.x line.